First published: Thu May 21 2020(Updated: )
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ChakraCore | <1.11.19 | |
Microsoft Edge | ||
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1065 is a remote code execution vulnerability in the ChakraCore scripting engine that allows an attacker to execute arbitrary code on a targeted system.
CVE-2020-1065 affects Microsoft ChakraCore version up to 1.11.19, Microsoft Edge, and certain versions of Microsoft Windows 10 and Windows Server 2019.
CVE-2020-1065 has a severity rating of 7.5 (high).
To fix CVE-2020-1065, update Microsoft ChakraCore to version 1.11.19 or higher, and apply the necessary patches for affected versions of Microsoft Edge, Windows 10, and Windows Server 2019.
You can find more information about CVE-2020-1065 on the NIST National Vulnerability Database (NVD), Microsoft Security Guidance Advisory, and the ChakraCore GitHub repository.